What we do with access to your code.
How Dravin AI handles access to your code: least privilege, no training on client code, no secrets in prompts, access removed within seven days.
LAST UPDATED 23 SEPTEMBER 2026
IN PLAIN LANGUAGE
Everything on this page is a practice we follow today. The short version:
- ACCESS
- Read-only for reviews. For build work, a branch, never main. Our own named accounts, multi-factor authentication, scoped and expiring tokens. You can revoke it at any time. Section 1
- WHERE YOUR CODE LIVES
- Your repository and our copy of it on our source-control host, our engineers’ encrypted single-user machines, our agents’ isolated environments and branch previews on our domain. Never a cloud drive or a chat tool. A one-off written report works from one read-only clone, deleted 30 days later. Section 2
- SECRETS
- Never in a chat, a ticket, a prompt, a commit or a screenshot. A secret found in your repository is reported the same day and rotated within 24 hours. Section 3
- DATA
- No production database on our machines unless a statement of work says so in writing. Anonymised or synthetic data by default. Section 4
- AI TOOLS
- Named before work starts, vetoable by you, and run on terms that prohibit training on your code. What they produce arrives as a pull request, and one of our engineers reads it before it merges. Section 5
- OFFBOARDING
- Within seven days of an engagement ending: every credential revoked; every clone, source-control copy, agent environment, preview, copy of your data and copy of a model we trained for you deleted; written confirmation of both. Section 7
- INCIDENTS
- Reported to you within 72 hours of us knowing, with what we know, what we have done and what we recommend. Section 8
- WHAT WE DO NOT CLAIM
- No ISO 27001, no SOC 2. If your procurement process needs a certification we do not hold, we say so on the first call. Section 10
TERMS USED ON THIS PAGE
- Least privilege
- The smallest access that will do the job. Section 1 sets out what that means for each kind of work.
- Named account
- An account of our own on your systems, so every action is attributable. Never a shared credential or a personal account of one of your staff.
- Scoped token
- A deployment credential limited to what it needs and set to expire, used instead of a long-lived key.
- Secret
- Any credential, key or token. It lives in environment variables or a secrets manager, and never goes into a chat, a ticket, a prompt, a commit or a screenshot.
- Offboarding
- What happens within seven days of an engagement ending: credentials revoked; clones, source-control copies, agent environments, previews, copies of your data and copies of models we trained for you deleted; written confirmation of both.
- Statement of work
- The signed document that describes an engagement. Some practices on this page, such as copying a production database, happen only when it says so in writing.
We hold no security certification. This page says exactly what we do. Everything on it is a practice we follow today, and it forms part of our terms.
1. Access
- Least privilege, always. Read-only access for reviews. For build work, write access to a branch, never to main, with your branch protection left on.
- Named accounts of our own on your systems, so every action is attributable. We never use a shared credential or a personal account of one of your staff.
- Multi-factor authentication on every account we hold, ours and yours.
- Scoped, expiring tokens for deployment rather than long-lived keys. We ask you to revoke anything you issued us the day the work ends, and we confirm what we held.
- You can revoke access at any time without telling us why.
2. Where your code lives
During an engagement your code is in these places, and nowhere else:
- Your own repository, which stays where it is. We work on branches of it. A change reaches main only as a pull request that one of our engineers has read and your branch protection allows to merge.
- Our engineers’ machines: full-disk encryption, a locked screen, current operating-system updates and no other user. One clone per engagement.
- A copy of your repository on our source-control host, for the length of the engagement (section 5 of our privacy notice).
- The isolated environments our coding agents run in, one per project and per agent, each on its own branch, under the same rules on secrets and data as our engineers (sections 3 and 4).
- Preview deployments on our domain. Automated checks run on each pull request, and each branch gets a preview so you can click through work in progress. A preview runs on anonymised or synthetic data, never on a copy of production data unless a statement of work says so.
- The AI coding tools named to you under section 5, on the terms set out there.
The hosting behind the source-control copy, the agent environments and the previews is listed by category in that section of the privacy notice and named to you before work starts. No client code goes on a shared or personal device, into a cloud drive or into a chat tool.
A one-off written report on your code, with no engagement after it, is written from one read-only clone. The clone and every copy of your material are deleted 30 days after the report.
3. Secrets
- A secret never goes into a chat, a ticket, a prompt, a commit or a screenshot.
- Configuration lives in environment variables or a secrets manager, never in the repository.
- If we find a secret committed to your repository, we tell you the same day and it is rotated within 24 hours. We treat it as urgent every time.
4. Data
- We do not copy production databases to our machines unless a statement of work says so in writing.
- Development and testing use anonymised or synthetic data by default.
- Personal data inside your systems is processed only on your instructions, as our privacy notice sets out.
5. AI tools and your code
- We use AI coding tools and say so. Every tool that touches your code runs on business terms that prohibit training on its input.
- Your code, data and documents are never used to train any model, ours or anyone else’s.
- We tell you which tools we intend to use before work starts, and you can veto any of them.
- What an AI tool produces reaches your repository only as a pull request on a branch, and one of our engineers reads it before it merges (section 6).
6. Code checks and dependencies
- Every pull request is read by one of our engineers before it merges.
- Dependencies are checked for known vulnerabilities on every pull request, and pinned.
- We do not add a dependency that we cannot explain the need for in the pull request.
7. Offboarding
Within seven days of an engagement ending:
- every credential we held is revoked, and we send you the list so you can check;
- every local clone, source-control copy, agent environment and preview deployment, every copy of your data, and every copy we hold of a model we trained for you (its weights, adapters, evaluation sets and training code), is deleted;
- you receive written confirmation of both.
8. Incidents
If we become aware of a security incident affecting your code or data, we tell you within 72 hours of knowing, with what we know, what we have done, and what we recommend. If in doubt, we report it.
9. Reporting a vulnerability
If you find a security problem in dravin.ai or in something we built, email [email protected] with “Security” in the subject line. We will not pursue anyone who reports in good faith.
10. What we do not claim
No ISO 27001, no SOC 2, no badges we have not earned. If a client’s procurement process requires a certification we do not hold, we say so on the first call.
Questions about this page
Write to [email protected] with “Security” in the subject line to report a problem, or without it to ask about anything on this page. We will not pursue anyone who reports a problem in good faith (section 9).